Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 718040

Summary: glsa 202003-48 marks nodejs-10.20.1 vulnerable
Product: Gentoo Security Reporter: Tomáš Mózes <hydrapolic>
Component: GLSA ErrorsAssignee: Gentoo Security <security>
Status: RESOLVED OBSOLETE    
Severity: normal    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---

Description Tomáš Mózes 2020-04-18 11:28:54 UTC
Version 10.20.1 is shown as vulnerable:

202003-48 [N] [local, remote] Node.js: Multiple vulnerabilities ( net-libs/nodejs-10.20.1 )
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2020-10-18 01:56:44 UTC
Package was marked as vulnerable because have no way to target multiple branches (package needs a at least subslots). There is not much we can do here: We could only ditch the GLSA which will cause that people only updating based on GLSA to not get the NodeJS upgrade.

But given that we are now (6 months after the report) at >=12.18 stable, I would keep GLSA and close bug as obsolete.